IP Library Patent Application 18898517
Patent Application
App. No. 18/898,517

AUTHENTICATION AND AUTHORIZATION OF REQUESTS FOR RESOURCES VIA AN ACCESS CONTROL SERVER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/898,517
Filed
Sep 26, 2024
Art Unit
2444
USPC
726/4
Abstract

Techniques for authenticating user access to a resource and providing access to the resource include non-transitory computer-readable media storing program instructions that, when executed by one or more processors associated with a first computing device, cause the one or more processors to perform a method including receiving, from a client device, a first request for an authentication token to access a resource and identifying a second computing device through which the resource is accessible. The method further includes transmitting a second request to the second computing device for the authentication token, receiving a signed authentication token from the second computing device, wherein the authentication token is signed by the second computing device and specific to the client device, and providing the signed authentication token to the client device.

Claims (48)

1 . One or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors associated with a first computing device, cause the one or more processors to perform a method comprising:

receiving, from a client device, a first request for an authentication token to access a resource;

identifying a second computing device through which the resource is accessible;

transmitting a second request to the second computing device for the authentication token;

receiving a signed authentication token from the second computing device, wherein the authentication token is signed by the second computing device and specific to the client device; and

providing the signed authentication token to the client device.

2 . The one or more non-transitory computer-readable media of claim 1 , wherein the first request from the client device comprises a first plurality of request parameters authenticated by the first computing device, the first plurality of request parameters including one or more of an identity of the client device or a user, an address of the second computing device, or the resource.

3 . The one or more non-transitory computer-readable media of claim 1 , wherein the client device transmits the signed authentication token and a third request to the second computing device to access the resource.

4 . The one or more non-transitory computer-readable media of claim 3 , wherein the client device obtains the resource directly from the second computing device in response to the second computing device validating the signed authentication token and the third request.

5 . The one or more non-transitory computer-readable media of claim 4 , wherein the resource provided to the client device is not provided to the first computing device.

6 . The one or more non-transitory computer-readable media of claim 4 , wherein a second plurality of request parameters are embedded into the signed authentication token by the second computing device.

7 . The one or more non-transitory computer-readable media of claim 6 , wherein validating the signed authentication token and the third request comprises verifying that the second plurality of request parameters matches a third plurality of request parameters embedded in the third request.

8 . The one or more non-transitory computer-readable media of claim 1 , further comprising authenticating a user associated with the client device.

9 . The one or more non-transitory computer-readable media of claim 8 , further comprising determining that the first request is authorized by verifying that the user is authorized to access the resource being requested.

10 . The one or more non-transitory computer-readable media of claim 1 , wherein the first computing device provides an address of the second computing device to the client device along with the signed authentication token.

11 . A computer-implemented method comprising:

receiving, in a first computing device from a client device, a first request for an authentication token to access a resource;

identifying a second computing device through which the resource is accessible;

transmitting a second request to the second computing device for the authentication token;

receiving a signed authentication token from the second computing device, wherein the authentication token is signed by the second computing device and specific to the client device; and

providing the signed authentication token to the client device.

12 . The computer-implemented method of claim 11 , wherein the first request from the client device comprises a first plurality of request parameters authenticated by the first computing device, the first plurality of request parameters including one or more of an identity of the client device or a user, an address of the second computing device, or the resource.

13 . The computer-implemented method of claim 11 , wherein the client device transmits the signed authentication token and a third request to the second computing device to access the resource.

14 . The computer-implemented method of claim 13 , wherein the client device obtains the resource directly from the second computing device in response to the second computing device validating the signed authentication token and the third request.

15 . The computer-implemented method of claim 14 , wherein the resource provided to the client device is not provided to the first computing device.

16 . The computer-implemented method of claim 14 , wherein a second plurality of request parameters are embedded into the signed authentication token by the second computing device.

17 . The computer-implemented method of claim 16 , wherein validating the signed authentication token and the third request comprises verifying that the second plurality of request parameters matches a third plurality of request parameters embedded in the third request.

18 . The computer-implemented method of claim 11 , further comprising authenticating a user associated with the client device.

19 . The computer-implemented method of claim 18 , further comprising determining that the first request is authorized by verifying that the user is authorized to access the resource being requested.

20 . The computer-implemented method of claim 11 , wherein the first computing device provides an address of the second computing device to the client device along with the signed authentication token.

21 . A system comprising:

a first computing device;

memory storing instructions; and

one or more processors coupled to the memory and, when executing the instructions, are configured to perform operations comprising:

receiving, from a client device, a first request for an authentication token to access a resource;

identifying a second computing device through which the resource is accessible;

transmitting a second request to the second computing device for the authentication token;

receiving a signed authentication token from the second computing device, wherein the authentication token is signed by the second computing device and specific to the client device; and

providing the signed authentication token to the client device.

22 . The system of claim 21 , wherein the first request from the client device comprises a first plurality of request parameters authenticated by the first computing device, the first plurality of request parameters including one or more of an identity of the client device or a user, an address of the second computing device, or the resource.

23 . The system of claim 21 , wherein the client device transmits the signed authentication token and a third request to the second computing device to access the resource.

24 . The system of claim 23 , wherein the client device obtains the resource directly from the second computing device in response to the second computing device validating the signed authentication token and the third request.

25 . The system of claim 24 , wherein the resource provided to the client device is not provided to the first computing device.

26 . The system of claim 24 , wherein a second plurality of request parameters are embedded into the signed authentication token by the second computing device.

27 . The system of claim 26 , wherein validating the signed authentication token and the third request comprises verifying that the second plurality of request parameters matches a third plurality of request parameters embedded in the third request.

28 . The system of claim 21 , further comprising authenticating a user associated with the client device.

29 . The system of claim 28 , further comprising determining that the first request is authorized by verifying that the user is authorized to access the resource being requested.

30 . The system of claim 21 , wherein the first computing device provides an address of the second computing device to the client device along with the signed authentication token.

Assignments (1)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →